๐Ÿ” CVE Alert

CVE-2026-105674

UNKNOWN 0.0

Predictable Media Stream Pre-Shared Key Vulnerability in TP-Link Tapo C325WB

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent network can recover the key and authenticate to the media streaming service without valid user credentials.ย  Successful exploitation may allow an unauthenticated adjacent-network attacker to access and take over live video and audio streams, compromising the confidentiality and integrity of camera media.

CWE CWE-330
Vendor tp-link systems inc.
Product tapo c325wb v2
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. tapo c325wb v2

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tapo c325wb v2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link Systems Inc. / Tapo C325WB v2
0 < V2_1.3.3 Build 260914

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/us/support/download/tapo-c325wb/#Firmware-Release-Notes tp-link.com: https://www.tp-link.com/en/support/download/tapo-c325wb/#Firmware-Release-Notes tp-link.com: https://www.tp-link.com/us/support/faq/5333/

Credits

Andrey Charikov, Check Point Research